Leidos currently has a need for a Sr Splunk SME for a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis, application development, and a 24x7x365 support staff. Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP) and is responsible for directing and coordinating detection and response activities performed by each Component SOC. Direction and coordination are achieved through a new shared DHS incident tracking system and other means of coordination and communication.
The selected candidate will provide overall engineering and design support for a very large distributed Splunk environment consisting of heavy forwarders, indexers, and search head servers, spanning security, performance, and operational roles. The Splunk SME will support the full system engineering life-cycle, including requirements analysis, design, development, integration, test, documentation, and implementation following defined best practices and operational workflows.
The candidate should be familiar with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk SME should be familiar with a Linux environment, editing and maintaining Splunk configuration files and apps. The Splunk SME Master will work with other Cybersecurity Engineering team members and will be required to interact with end users to gather requirements, perform troubleshooting, and provide assistance with the creation of Splunk search queries and dashboards. The Splunk SME Master will be required to interact with senior management, as necessary.
Masters Degree with 15 years of prior relevant IT experience or PhD with 13 years of prior experience and S plunk Enterprise Certified Architect certificate and /or SplunkEnterprise Certified Admin certificate is preferred. Splunk Enterprise Certified Architect has a thorough understanding of Splunk Deployment Methodology and best‑practices for planning, data collection, and sizing for a distributed deployment and is able to manage and troubleshoot a standard distributed deployment with indexer and search head clustering. This highly technical certification, designed for Enterprise architects, demonstrates an individual's ability to deploy, manage, and troubleshoot complex Splunk Enterprise environments. A Splunk Enterprise Certified Admin manages various components of Splunk Enterprise on a daily basis, including license management, indexers and search heads, configuration, monitoring, and getting data into Splunk. This certification demonstrates an individual's ability to support the day-to-day administration and health of a Splunk Enterprise environment
4+ years of experience in a senior Splunk role
3+ Years experience in Linux and SQL/ODBC interfaces
2+ Years experience in app interface development, using REST API's
Previous project management experience.
ITIL Change & Configuration Management
- Experience in SQL
- Experience in other systems and network management products.
- Current or former completed Splunk training